2026 CVE Vulnerabilities
53,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25375 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allow... |
| CVE-2026-25374 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in raratheme Spa and Salon spa-and-salon allows Exploiting Incorrectly Configured Ac... |
| CVE-2026-25372 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-25370 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Exploiting Incorrectly Conf... |
| CVE-2026-25368 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Exploiting Incorr... |
| CVE-2026-25367 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in NooTheme CitiLights noo-citilights allows Exploiting Incorrectly Configured Acces... |
| CVE-2026-25364 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting In... |
| CVE-2026-25363 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in FooPlugins FooGallery foogallery allows Exploiting Incorrectly Configured Access ... |
| CVE-2026-25362 | MEDIUM | 5.9 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooGall... |
| CVE-2026-25348 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configure... |
| CVE-2026-25343 | MEDIUM | 5.9 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS ... |
| CVE-2026-25338 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistan... |
| CVE-2026-25337 | MEDIUM | 5.4 | 0.1% | Feb 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpcoachify Coachify coachify allows Cross Site Request Forgery.This i... |
| CVE-2026-25336 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in wpcoachify Coachify coachify allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-25335 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-pr... |
| CVE-2026-25333 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in peregrinethemes Shopwell shopwell allows Exploiting Incorrectly Configured Access... |
| CVE-2026-25332 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Exploiting... |
| CVE-2026-25331 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activ... |
| CVE-2026-25330 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrec... |
| CVE-2026-25329 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Inc... |
| CVE-2026-25325 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress... |
| CVE-2026-25324 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master... |
| CVE-2026-25323 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in MiKa OSM osm allows Exploiting Incorrectly Configured Access Control Security Lev... |
| CVE-2026-25322 | MEDIUM | 5.4 | 0.1% | Feb 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in PublishPress PublishPress Revisions revisionary allows Cross Site Req... |
| CVE-2026-25321 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in PSM Plugins SupportCandy supportcandy allows Exploiting Incorrectly Configured Ac... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now